szAppName : firefox.exe szAppVer : 1.9.0.3685 szModName : hungapp
szModVer : 0.0.0.0 offset : 00000000
a w raporcie błędów wyskakuje:
C:\DOCUME~1\BUA~1\USTAWI~1\Temp\WERaeda.dir00\firefox.exe.mdmp
C:\DOCUME~1\BUA~1\USTAWI~1\Temp\WERaeda.dir00\appcompat.txt
Raportuj ten postOdpowiedz z cytatem Proźba o sprawdzenie logów.
przez rDz » Dzisiaj, 22:04
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
plik wynikowy zcombofix:
http://wklej.eu/index.php?id=07028f70e6
ComboFix 10-03-09.04 - buła 2010-03-09 22:40:00.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.502.184 [GMT 1:00]
Uruchomiony z: c:\documents and settings\buła\Pulpit\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\pdfforge Toolbar\SearchSettings.dll
c:\windows\system32\ieuinit.inf
.
((((((((((((((((((((((((( Pliki utworzone od 2010-02-09 do 2010-03-09 )))))))))))))))))))))))))))))))
.
2010-03-09 21:01 . 2010-03-09 21:22 -------- d-----w- c:\program files\trend micro
2010-03-09 21:01 . 2010-03-09 21:08 -------- d-----w- C:\rsit
2010-03-09 13:45 . 2010-03-09 13:45 -------- d-----w- c:\program files\Opera
2010-03-09 13:10 . 2010-03-09 13:11 -------- d-----w- c:\program files\Apoint2K
2010-03-09 13:10 . 2004-11-16 03:22 101874 ----a-w- c:\windows\system32\drivers\Apfiltr.sys
2010-03-09 13:10 . 2003-08-30 05:37 87865 ----a-w- c:\windows\system32\Vxdif.dll
2010-03-09 13:09 . 2006-03-18 19:22 89541 ----a-w- c:\windows\agrsmmsg.exe
2010-03-09 13:09 . 2003-10-31 21:59 45056 ----a-w- c:\windows\system32\csellang.dll
2010-03-09 13:09 . 2010-03-09 13:09 -------- d-----w- c:\program files\ltmoh
2010-03-09 13:09 . 2005-04-06 18:53 110592 ----a-w- c:\windows\system32\cselect.exe
2010-03-09 13:07 . 2005-05-03 15:10 68096 ------w- c:\windows\agrsmdel.exe
2010-03-09 13:05 . 2010-03-09 13:05 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-03-09 13:05 . 2010-03-09 13:05 -------- d-----w- c:\windows\system32\config\systemprofile\Dane aplikacji\Intel
2010-03-09 13:05 . 2010-03-09 13:05 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Intel
2010-03-09 12:57 . 2005-08-18 08:45 26880 ----a-w- c:\windows\system32\drivers\WOWHD_kern_i386.sys
2010-03-09 12:57 . 2006-12-13 11:22 46592 ----a-w- c:\windows\system32\drivers\Tvs.sys
2010-03-09 12:57 . 2005-10-25 16:33 36736 ----a-w- c:\windows\system32\drivers\CSIIDecoder_kern_i386.sys
2010-03-09 12:57 . 2005-01-25 13:35 29184 ----a-w- c:\windows\system32\drivers\TSXT_kern_i386.sys
2010-03-09 12:50 . 2005-11-01 05:17 135168 ----a-w- c:\windows\system32\RtlCPAPI.dll
2010-03-09 12:49 . 2005-05-04 05:43 69632 ----a-w- c:\windows\Alcmtr.exe
2010-03-09 12:48 . 2010-03-09 12:48 -------- d-----w- c:\windows\system32\SDA
2010-03-09 12:47 . 2005-08-11 13:33 45056 ----a-w- c:\windows\system32\TPwrCfg.dll
2010-03-09 12:47 . 2005-08-11 13:33 40960 ----a-w- c:\windows\system32\TPSAddin.dll
2010-03-09 12:47 . 2005-08-11 13:33 266240 ----a-w- c:\windows\system32\TPSMain.exe
2010-03-09 12:47 . 2005-08-11 13:33 40960 ----a-w- c:\windows\system32\TPSBattM.exe
2010-03-09 12:47 . 2005-08-11 13:33 49152 ----a-w- c:\windows\system32\TPSDel.dll
2010-03-09 12:47 . 2005-08-11 13:33 40960 ----a-w- c:\windows\system32\TPSMainCtl.dll
2010-03-09 12:47 . 2005-08-11 13:33 86016 ----a-w- c:\windows\system32\CpuPerf.dll
2010-03-09 12:47 . 2005-08-11 13:33 49152 ----a-w- c:\windows\system32\TPSTrace.dll
2010-03-09 12:47 . 2005-08-11 13:33 77824 ----a-w- c:\windows\system32\TPwrReg.dll
2010-03-09 12:11 . 2005-05-17 09:06 94208 ----a-w- c:\windows\system32\TCtrlCommon.dll
2010-03-09 12:03 . 2003-01-30 01:35 12032 ----a-w- c:\windows\system32\drivers\Netdevio.sys
2010-03-09 08:16 . 2010-03-09 08:16 -------- d-----w- c:\windows\system32\KB905474
2010-03-09 08:16 . 2009-03-10 21:26 1436544 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2010-03-09 08:16 . 2009-03-10 21:18 455048 ----a-w- c:\windows\system32\KB905474\wgasetup.exe
2010-03-08 18:43 . 2010-03-08 18:43 -------- d-----w- c:\program files\Kreślarz
2010-03-08 18:39 . 2010-03-08 18:39 -------- d-----w- c:\program files\Gadu-Gadu
2010-03-08 18:31 . 2010-03-08 18:31 -------- d-----w- c:\documents and settings\NetworkService\Ustawienia lokalne\Dane aplikacji\cache
2010-03-08 18:28 . 2010-03-08 18:28 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Gadu-Gadu 10
2010-03-08 18:10 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-08 18:10 . 2008-06-14 17:36 273024 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-08 18:10 . 2008-06-14 17:36 273024 ------w- c:\windows\system32\drivers\bthport.sys
2010-03-08 18:05 . 2009-12-09 10:11 2146816 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-03-08 18:05 . 2009-12-09 10:11 2067328 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-03-08 18:05 . 2009-12-09 10:11 2025472 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-03-08 17:59 . 2008-07-09 07:57 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-03-08 17:59 . 2010-03-09 21:14 -------- d--h--w- c:\windows\$hf_mig$
2010-03-08 17:35 . 2010-03-08 17:36 -------- d-----w- c:\program files\Ahead
2010-03-08 17:29 . 2010-03-08 17:29 -------- d-----w- c:\windows\system32\config\systemprofile\Dane aplikacji\Application Updater
2010-03-08 17:29 . 2010-03-08 17:29 -------- d-----w- c:\program files\Application Updater
2010-03-08 17:29 . 2010-03-09 21:42 -------- d-----w- c:\program files\pdfforge Toolbar
2010-03-08 17:28 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2010-03-08 17:28 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2010-03-08 17:28 . 2010-03-08 17:29 -------- d-----w- c:\program files\PDFCreator
2010-03-08 17:21 . 2010-03-08 17:48 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-08 17:16 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-03-08 17:16 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2010-03-08 17:16 . 2010-03-08 17:16 -------- d-----w- c:\program files\Microsoft Works
2010-03-08 17:15 . 2010-03-08 17:15 -------- d-----w- c:\program files\MSBuild
2010-03-08 17:12 . 2010-03-08 17:15 -------- d-----w- c:\windows\SHELLNEW
2010-03-08 17:12 . 2010-03-08 17:17 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2010-03-08 17:11 . 2010-03-08 17:11 -------- d-----r- C:\MSOCache
2010-03-08 17:07 . 2010-03-08 17:07 -------- d-----w- c:\windows\system32\Lang
2010-03-08 17:07 . 2006-02-07 19:40 143360 ----a-w- c:\windows\system32\igfxres.dll
2010-03-08 16:55 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-03-08 16:55 . 2003-12-05 03:48 77824 ----a-w- c:\windows\system32\tosmreg.exe
2010-03-08 16:51 . 2005-06-02 14:33 102384 ----a-w- c:\windows\system32\drivers\meiudf.sys
2010-03-08 16:51 . 2004-08-28 11:37 155648 ----a-w- c:\windows\system32\RAMASST.exe
2010-03-08 16:51 . 2010-03-08 16:51 -------- d-----w- c:\program files\DVD-RAM
2010-03-08 16:51 . 2005-04-22 15:36 135168 ----a-w- c:\windows\system32\DVDMenu.dll
2010-03-08 16:51 . 2004-08-28 11:33 110592 ----a-w- c:\windows\system32\DVDRAMSV.exe
2010-03-08 16:50 . 2004-02-14 00:49 356352 ----a-w- c:\windows\EMCRI.dll
2010-03-08 16:45 . 2010-03-09 13:05 -------- d-----w- c:\program files\Intel
2010-03-08 16:41 . 2010-03-09 12:59 -------- d-----w- c:\program files\TOSHIBA
2010-03-08 16:37 . 2008-04-13 23:09 5376 -c--a-w- c:\windows\system32\dllcache\mspclock.sys
2010-03-08 16:28 . 2006-03-18 18:36 1155584 ----a-w- c:\windows\system32\drivers\AGRSM.sys
2010-03-08 16:27 . 2006-03-23 20:59 37888 ----a-w- c:\windows\system32\drivers\ESD7SK.sys
2010-03-08 16:27 . 2006-03-23 20:59 74752 ----a-w- c:\windows\system32\drivers\ESM7SK.sys
2010-03-08 16:27 . 2006-03-23 20:59 61056 ----a-w- c:\windows\system32\drivers\EMS7SK.sys
2010-03-08 15:48 . 2004-01-11 22:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-03-08 15:48 . 2003-03-19 03:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-08 15:48 . 2010-03-08 15:48 -------- d-----w- c:\program files\Real Alternative
2010-03-08 15:42 . 2009-12-12 14:15 178176 ----a-w- c:\windows\system32\unrar.dll
2010-03-08 15:42 . 2010-03-08 15:43 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-03-08 15:27 . 2010-03-08 15:28 -------- d-----w- c:\program files\SubEdit-Player
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-09 21:19 . 2001-10-26 16:15 49910 ----a-w- c:\windows\system32\perfc015.dat
2010-03-09 21:19 . 2001-10-26 16:15 356068 ----a-w- c:\windows\system32\perfh015.dat
2010-03-09 13:10 . 2010-03-08 13:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-09 12:49 . 2010-03-08 16:37 -------- d-----w- c:\program files\Realtek
2010-03-08 18:18 . 2010-03-08 18:17 -------- d-----w- c:\program files\Winamp
2010-03-08 18:17 . 2010-03-08 18:17 -------- d-----w- c:\program files\Winamp Detect
2010-03-08 16:37 . 2010-03-08 13:20 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-08 13:32 . 2010-03-08 13:32 0 ----a-w- c:\windows\nsreg.dat
2010-03-08 13:01 . 2010-03-08 12:41 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-08 12:56 . 2010-03-08 12:56 -------- d-----w- c:\program files\ESET
2010-03-08 12:56 . 2010-03-08 12:56 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\ESET
2010-03-08 12:43 . 2010-03-08 12:43 -------- d-----w- c:\program files\microsoft frontpage
2010-03-08 12:41 . 2010-03-08 12:41 -------- d-----w- c:\program files\Usługi online
2010-03-08 12:38 . 2010-03-08 12:38 21856 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-31 16:50 . 2008-04-13 22:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:10 . 2008-04-14 20:50 669696 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:10 . 2008-04-14 20:50 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-17 07:42 . 2010-03-08 12:37 345088 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2008-04-14 20:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
2010-01-08 02:17 700416 ----a-w- c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"= "c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll" [2010-01-08 700416]
[HKEY_CLASSES_ROOT\clsid\{b922d405-6d13-4a2b-ae89-08a030da4402}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-09-16 1447168]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2010-01-08 974848]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-12-18 39424]
"NDSTray.exe"="NDSTray.exe" [BU]
"TFncKy"="TFncKy.exe" [BU]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
"TPSMain"="TPSMain.exe" [2005-08-11 266240]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-18 16143872]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-12-21 1077330]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2006-04-12 638976]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2006-04-04 53248]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2006-02-02 73728]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-05-12 118784]
"Zooming"="ZoomingHook.exe" [2005-06-06 24576]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"AGRSMMSG"="AGRSMMSG.exe" [2006-03-18 89541]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-24 196608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-3-8 113664]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2010-3-8 155648]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-08-18 34312]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-09-17 468224]
.
Zawartość folderu 'Zaplanowane zadania'
2010-03-09 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-03-09 21:18]
.
.
------- Skan uzupełniający -------
.
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\buła\Dane aplikacji\Mozilla\Firefox\Profiles\q15hdckb.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-09 22:43
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2010-03-09 22:44:27
ComboFix-quarantined-files.txt 2010-03-09 21:44
Przed: 23 518 187 520 bajtów wolnych
Po: 23 691 218 944 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 58FC55D2D0258FB21361A762A6BE90D6
--------------------------------------------------------------------------------
Prosze o pomoc bo sama nie daje rady
